CVE-2023-3864: Snowsoftware Snow License Manager

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal.

Affected products

  • Snowsoftware Snow License Manager: from 8.0.0, up to and including 9.30.1

Published 2023-08-11. Last modified 2026-06-17.